Bug 1419799 - Fix nsContentUtils::IsInSameAnonymousTree in Shadow DOM

Tag #1375
This commit is contained in:
Matt A. Tobin 2020-04-17 07:23:48 -04:00 committed by Roy Tam
commit 6d8e6e8955
3 changed files with 19 additions and 11 deletions

View file

@ -0,0 +1,17 @@
<html>
<head>
<script>
try { o1 = document.createElement('textarea') } catch(e) { }
try { o2 = document.createElement('div') } catch(e) { }
try { o3 = document.createElement('map') } catch(e) { }
try { document.documentElement.appendChild(o2) } catch(e) { }
try { o2.appendChild(o1) } catch(e) { }
try { document.documentElement.getClientRects() } catch(e) { }
try { o4 = o2.attachShadow({ mode: "open" }); } catch(e) { }
try { o1.appendChild(o3) } catch(e) { }
try { o5 = o3.parentElement } catch(e) { }
try { o3.outerHTML = "\n" } catch(e) { }
try { o4.prepend("", o5, "") } catch(e) { }
</script>
</head>
</html>

View file

@ -210,3 +210,4 @@ load 1251361.html
load 1304437.html
pref(clipboard.autocopy,true) load 1385272-1.html
pref(dom.webcomponents.customelements.enabled,true) load 1341693.html
pref(dom.webcomponents.enabled,true) load 1419799.html

View file

@ -4955,17 +4955,7 @@ nsContentUtils::IsInSameAnonymousTree(const nsINode* aNode,
return aContent->GetBindingParent() == nullptr;
}
const nsIContent* nodeAsContent = static_cast<const nsIContent*>(aNode);
// For nodes in a shadow tree, it is insufficient to simply compare
// the binding parent because a node may host multiple ShadowRoots,
// thus nodes in different shadow tree may have the same binding parent.
if (aNode->IsInShadowTree()) {
return nodeAsContent->GetContainingShadow() ==
aContent->GetContainingShadow();
}
return nodeAsContent->GetBindingParent() == aContent->GetBindingParent();
return aNode->AsContent()->GetBindingParent() == aContent->GetBindingParent();
}
class AnonymousContentDestroyer : public Runnable {